Backup e disaster recovery
Sicurezza

Firewall Configuration Guide for Cove’s Move to Mutual TLS

A Disclaimer Before You Begin

This guide is provided for reference to help you get started and is not official documentation from your firewall vendor. Menu names, steps, and settings may vary by firmware version or configuration. Always consult your firewall vendor’s documentation or support team for guidance specific to your environment before making changes.

Stopping the Man in the Middle

Man-in-the-middle (MITM) attacks let an attacker sit between two systems, intercept their traffic, and read or alter it without either side noticing. On an unprotected connection, that means backup traffic — including credentials and business data — could be exposed in transit.

That’s why we’re upgrading the connection between Backup Manager and the N-able cloud from one-way TLS to mutual TLS (mTLS), which adds client-side certificate authentication on top of encryption. Both sides now verify each other’s identity before any data moves, closing the gap MITM attacks rely on and keeping backup traffic genuinely end to end (E2E) encrypted with no proxy able to decrypt and re-encrypt it in the middle.

Preparing for the Move to mTLS

Backup Manager will be moving to mTLS which will validate the full TLS certificate chain on its connections. There is no client-side setting to disable this check, so any firewall or proxy that re-signs TLS (SSL/TLS inspection, DPI-SSL, HTTPS content inspection) will break backups unless the relevant Cove domains are explicitly excluded from that inspection.

Therefore, Cove must be excluded from TLS inspection before November 2nd, 2026. To help you get started, we’ve put together this configuration guide for the most commonly used firewalls.

For every firewall below, the fix is the same in principle: add cloudbackup.management and *.cloudbackup.management to that firewall’s TLS/SSL inspection exclusion or allow list, using domain or SNI matching rather than IP matching.

Quick Reference

Domains to exclude on every firewall that supports domain/SNI-based TLS exceptions:

  • cloudbackup.management
  • *.cloudbackup.management (covers all storage nodes automatically, e.g. < home-node >.cloudbackup.management and < home-node >-webrcg.cloudbackup.management)

Where to find a device’s home node: The home node name (e.g., us-atl-08-02) is visible in the device’s Backup Manager URL, or on the device’s overview page in the Cove Management Console.

For more information, you can refer to our knowledge base.

1. Cisco® Meraki™ MX

Meraki’s HTTPS Inspection feature (MX OS 26.2+, Advanced Security or SD-WAN+ license) can decrypt and inspect HTTPS traffic, then re-encrypt it. It supports an L7 allow list matching destination hostname with wildcards.

Official documentation:

2. Fortinet® FortiGate®

FortiGate’s SSL/SSH Inspection profile supports exempting destinations by wildcard FQDN, matched against the TLS SNI field — this works independently of DNS resolution.

Official documentation:

Note: SSL exemption only applies when the policy’s Inspection Method is Full SSL Inspection (deep inspection). If the policy uses certificate inspection only, no exemption is needed.

3. SonicWall® (SonicOS® / DPI-SSL)

SonicWall’s DPI-SSL Client (and Server, if applicable) SSL inspection supports domain-based exclusions via Common Name Exclusions, or via FQDN Address Objects added to the Exclude list.

Official documentation:

WatchGuard® Firebox®

The Firebox’s HTTPS-Proxy action supports Domain Name Rules, which take precedence over the predefined Content Inspection Exceptions list.

Official documentation:

5. Sophos® Firewall (XGS Series)

Sophos Firewall matches TLS exclusions by SNI, which is most efficiently done through a URL group rather than an FQDN host object (FQDN hosts require DNS lookups and are less efficient).

Official documentation:

6. Palo Alto Networks® (PAN-OS®)

PAN-OS matches its SSL Decryption Exclusion list against both the TLS SNI in the Client Hello and the CN/SAN in the server certificate, so the exclusion does not depend on DNS resolution or a fixed IP, and wildcards are supported.

Official documentation:

Next Steps

Mutual TLS gives Cove backup traffic stronger protection against interception. To keep backups running without disruption, make sure the exclusion is in place before the deadline. Use the steps above to help configure your specific firewall and reach out to your firewall vendor if you need help beyond what’s covered here. If you run into issues on the Cove side, our support team is ready to help.

© N‑able Solutions ULC e N‑able Technologies Ltd. Tutti i diritti riservati.

Il presente documento viene fornito per puro scopo informativo e i suoi contenuti non vanno considerati come una consulenza legale. N‑able non rilascia alcuna garanzia, esplicita o implicita, né si assume alcuna responsabilità legale per quanto riguarda l’accuratezza, la completezza o l’utilità delle informazioni qui contenute.

N-ABLE, N-CENTRAL e gli altri marchi e loghi di N‑able sono di esclusiva proprietà di N‑able Solutions ULC e N‑able Technologies Ltd. e potrebbero essere marchi di common law, marchi registrati o in attesa di registrazione presso l’Ufficio marchi e brevetti degli Stati Uniti e di altri paesi. Tutti gli altri marchi menzionati qui sono utilizzati esclusivamente a scopi identificativi e sono marchi (o potrebbero essere marchi registrati) delle rispettive aziende.